CVE-2026-17598
Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.
| CWE | CWE-915 |
| Vendor | sonatype |
| Product | nexus repository 3 |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonatype nexus repository 3
Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sonatype / Nexus Repository 3
3.91.0 < 3.95.0
References
Credits
Mayur Udiniya aka roughwire (https://x.com/roughwire/)